CVE-2009-0689 EXPLOIT
Patch early
A public exploit exists.
Description
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 28.05% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-07-01 |
| Last modified | 2026-06-16 |
Affected (6)
| Vendor | Product |
|---|---|
| freebsd | freebsd |
| k-meleon project | k-meleon |
| mozilla | firefox |
| mozilla | seamonkey |
| netbsd | netbsd |
| openbsd | openbsd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apple Mac OSX 10.x - 'libc/strtod(3)' Memory Corruption | 2010-01-08 |
| exploit-db | MATLAB R2009b - 'dtoa' Implementation Memory Corruption | 2010-01-08 |
| exploit-db | Sunbird 0.9 - Array Overrun Code Execution | 2009-12-11 |
| exploit-db | Opera Web Browser 10.01 - 'dtoa()' Remote Code Execution | 2009-11-20 |
| exploit-db | KDE 4.3.3 - KDELibs 'dtoa()' Remote Code Execution | 2009-11-20 |
| exploit-db | KDE KDELibs 4.3.3 - Remote Array Overrun | 2009-11-19 |
| exploit-db | SeaMonkey 1.1.8 - Remote Array Overrun | 2009-11-19 |
| exploit-db | K-Meleon 1.5.3 - Remote Array Overrun | 2009-11-19 |
| exploit-db | Opera 10.01 - Remote Array Overrun | 2009-11-19 |
| exploit-db | Mozilla Firefox 3.5.3 - Floating Point Conversion Heap Overflow | 2009-10-27 |
| exploit-db | BSD (Multiple Distributions) - 'gdtoa/misc.c' Memory Corruption | 2009-05-26 |
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
- http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
- http://rhn.redhat.com/errata/RHSA-2014-0311.html
- http://rhn.redhat.com/errata/RHSA-2014-0312.html
- http://secunia.com/advisories/37431
- http://secunia.com/advisories/37682
- http://secunia.com/advisories/37683
- http://secunia.com/advisories/38066
- http://secunia.com/advisories/38977
- http://secunia.com/advisories/39001
- http://secunia.com/secunia_research/2009-35/
- http://securityreason.com/achievement_securityalert/63
- http://securityreason.com/achievement_securityalert/69
- http://securityreason.com/achievement_securityalert/71
- http://securityreason.com/achievement_securityalert/72
- http://securityreason.com/achievement_securityalert/73
- http://securityreason.com/achievement_securityalert/75
→ the Explorer · watch your stack · NVD